In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application is vulnerable if it is using HeaderHttpSessionIdResolver.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 07 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: vmware
Published: 2023-04-13T00:00:00.000Z
Updated: 2025-02-07T16:41:34.511Z
Reserved: 2022-11-01T00:00:00.000Z
Link: CVE-2023-20866
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-02T09:21:32.350Z
 NVD
                        NVD
                    Status : Modified
Published: 2023-04-13T20:15:08.263
Modified: 2025-02-07T17:15:24.140
Link: CVE-2023-20866
 Redhat
                        Redhat